File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -9,7 +9,7 @@ advisory:
99 gem : faraday
1010 cve : 2026-33637
1111 ghsa : 5rv5-xj5j-3484
12- url : https://github.com/lostisland/faraday/security/advisories/GHSA-5rv5-xj5j-3484
12+ url : https://nvd.nist.gov/vuln/detail/CVE-2026-33637
1313 title : Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2 - protocol-relative
1414 URI objects still bypass host scoping
1515 date : 2026-05-18
@@ -38,7 +38,7 @@ advisory:
3838 that believe they are constrained to a fixed base URL. If the
3939 connection carries default headers or query parameters, those
4040 values are forwarded to the attacker-selected host.
41- cvss_v3 : 0.0
41+ cvss_v3 : 6.5
4242 unaffected_versions :
4343 - " < 2.0.0"
4444 patched_versions :
@@ -50,5 +50,4 @@ advisory:
5050 - https://github.com/lostisland/faraday/security/advisories/GHSA-5rv5-xj5j-3484
5151 - https://github.com/advisories/GHSA-33mh-2634-fwr2
5252 - https://github.com/advisories/GHSA-5rv5-xj5j-3484
53- notes : " - ZERO CVSS value in GHSA and NVD\n "
5453---
Original file line number Diff line number Diff line change @@ -58,6 +58,7 @@ advisory:
5858 - " >= 3.2.0"
5959 related :
6060 url :
61+ - https://www.cve.org/CVERecord?id=CVE-2026-45363
6162 - https://github.com/jwt/ruby-jwt/security/advisories/GHSA-c32j-vqhx-rx3x
6263 - https://github.com/jwt/ruby-jwt/commit/db560b769a07bd9724e77ff505011ac01872106f
6364 - https://github.com/jwt/ruby-jwt/releases/tag/v3.2.0
You can’t perform that action at this time.
0 commit comments